Turns out there is/was an exploit in the e107 CMS that resulted in a lot of sites using it getting nailed. We were one of them... The entire 'AvaMods' domain directory got wiped out, twice.. Thankfully I have backups of a lot of the stuff, but some of it isnt exactly up to date and there was also quite a bit I didnt have backups of. Most things seems to be back up and running now but it'll probably take me some time to get some other little things going again.
Ive updated e107 to the latest version and did some other 'possible' fixes to prevent this exploit from happening again, so hopefully things will be fine from here on. This has also got me contemplating re-doing the website over again, maybe with a different CMS or just a simple page from scratch with a better download system (possibly integrated into the forums)
Ive disabled the DoD Block Exploits download from here as well as on DoDplugins.net due to someone 'complaining' about the source code not being distributed with the plugin to Bailopan of which he emailed me about..
I bet we can all take an accurate guess as to who it probably was that complained.. But in either case it doesnt hurt me/us any, it only hurts other server admins...
Here's yet another long overdue update to the DoD Block Exploits plugin... Quite a few efficiency improvements as well as a new bug fix and a detect/block ability of the latest dod exploit (client freeze exploit). The SQL web front-end has also been updated and due to the new exploit addition, you will need to update to the latest ini file as the new entry does not allow the plugin to auto update the ini file version number
- 12.09.09 - Version 6.0 (Final) Converting majority of FakeMeta over to Engine Added 'Stick Grenade EX fix' (thanks VET) Improved some variable usage Changed some if statements to switches Used formatex instead of format in a few places Increased variable size for vault data Improved vault data string formatting Added caching of is_user_connected status Added caching of is_user_bot status Added PCVAR usage for getting mp_allowspectators value Improved some other variable array sizes Added 'Client Freeze Exploit' detection/block
- SQL Version Updated web front-end to v1.3 to include new 'Client Freeze Exploit' Fixed web front-end from cutting off names containing "<" Used formatex instead of format in a few places Set SQL log query variable to static
People with reserved slots will now starting getting bonuses.. What they actually get will probably change over time but for right now they get 2 extra smoke grenades and 1 extra meth syringe